Jump to content

georgeescott

Members
  • Posts

    175
  • Joined

  • Last visited

Reputation

446 Excellent

1 Follower

About georgeescott

Recent Profile Visitors

428 profile views
  1. I’ve changed jobs since I last posted so won’t be able to provide much more info on the issue, but i heard that a BIOS update from HP (not the one via Windows Update) then initiated a TPM update and that resolved it for the HP 255 G8’s. Hopefully one of my previous colleagues will post here with more info on it and if the ticket is still open with HP for the other models affected. I assume latest BIOS from HP doesn’t work for the 255 G7’s. Worth logging a ticket with HP for them if they’re still under warranty.
  2. Took them over a year to reach out after I submitted the form for canva education…. They’re contactable through [email protected] or [email protected]. Usually get a reply within a few days.
  3. So... further to my previous post about affected laptops, we've recently purchased a non-DfE laptop that's also affected by this issue. The model is: HP 255 G8 (AMD Ryzen 5 5500U CPU, AMD TPM) INFORMATION_EK_CERTIFICATE Comes with TPM Version: 3.87.0.5 out of the box. No TPM firmware update via Windows Update or OEM Luckily this newer one is still under warranty so I've logged a case with HP today. I've asked them to update HP Commercial Notebook PCs - TPM Attestation May Time Out During Microsoft Autopilot Pre-Provisioning once/if they release a new TPM version. I've reported TPM issues with HP 245 G8, HP 250 G7, HP 255 G7 and HP 255 G8 to them. Let me know if any other HP models are affected.
  4. We’ve encountered something slightly similar, where if you delete a cached user (assuming this is the first time they’ve used the device) on Windows 11, the next time they sign in, none of the SSO policies work. So users have to manually sign in to OneDrive/Edge/M365 apps etc. I wonder if some shared device policies have cleaned up cached logins or something? Or it’s a similar type of bug perhaps.
  5. Might be possible doing it through M365 MyStaff https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/my-staff-configure
  6. Yep, we're having this issues too. If you clear browser cache (or just the Media Foundation data), that seems to be fixing it for us on affected users.
  7. Does your RDS server have the same ‘Site to Zone Assignment’ GPO settings as the rest of your devices? https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-install-custom#enabling-single-sign-on
  8. Role: IT Security and Infrastructure Engineer Richard Huish College has a strong reputation regionally in its offer of a wide range of A level and vocational courses in Taunton and the surrounding areas in Somerset. We are currently seeking a permanent full time IT Security and Infrastructure Engineer. To provide first class IT support services across Huish with a focus on the security and robustness of all IT systems. This will involve maintaining and deploying solutions to facilitate safe and secure classroom and online learning, and secure access to support services. As well as ensuring that the Huish systems meet legal requirements and are kept working. Working within a highly skilled team, it will provide you with opportunities to expand your knowledge in all areas of IT. This post will also require a knowledge of project management and experience in deploying complex solutions. Richard Huish is a welcoming, supportive and exciting place to work, which promotes a culture of respect and high aspirations for both staff and students. · Salary: SP 21 – 23 (£35,451 - £37,385) · Hours: 37 hours a week, all year round · Contract: Full time, permanent · Closing Date: 26th September 2024 https://www.tes.com/jobs/vacancy/it-security-and-infrastructure-engineer-somerset-2109687
  9. This is workplace join effectively isn’t it? So they’d show as ‘registered’ and not ‘joined’ or ‘hybrid joined’ wouldn’t it? So we can only control them with limited policies I think. We’ve gone for user-driven enrollment and then we remove the primary user from the device. Although we still need to test if a Device Enrollment Manager will be a more viable workaround: http:// https://learn.microsoft.com/en-us/mem/intune/enrollment/device-enrollment-manager-enroll.
  10. We're also deploying a custom start2.bin file as per https://quake.blog/configure-windows-11-start-menu-using-only-group-policy.html. The ConfigureStartPins registry key workaround sadly seems to have been 'fixed' in 23H2. We set 'Apply once and do not reapply' so that they can customise it after they get the default one.
  11. I was told by Intel and Microsoft that the OEM has to fix the TPM firmware bugs. They’ve fixed it in other laptop models with a firmware update, so just need to issue one for this model. You can use it in user-driven mode, just not self-deploy or use pre-provisioning as the TPM bug then breaks this.
  12. Nope, you’ll need to log a ticket with HP to fix the TPM firmware I’m afraid. They won’t do it if they’re not under warranty though. That’s where I got to.
  13. You can mass-collect the hardware hashes a few ways: https://learn.microsoft.com/en-us/autopilot/add-devices#collect-the-hardware-hash. We did ours primarily using Configuration Manager (SCCM). We then imported the CSV from ConfigMgr in to Autopilot and already had dynamic device groups set up to assign them an Autopilot profile. We also did some using Windows Autopilot deployment for existing devices (only supports user-driven, not self-deploy) which uses a JSON file during a task sequence to enrol them and register the device in Autopilot. For all of our devices, we did a clean Windows 11 install, worked well! You could probably modify the PowerShell script to save the hash to a SMB share or something if you don't have ConfigMgr though.
  14. We’ve been able to make it work without any need to download the NPS certificate to student devices. We’ve tested it working with either a Public NPS certificate or with the NPS server cert generated from the CA. If their Android phone still has the option, select: CA certificate: Don’t validate If they don’t have that option (usually on Android 11+), select: CA certificate: Use system certificates or Use installed certificates (same setting but named differently on some phones) Online certificate status: Don’t validate Domain: yourdomain.com or ad.your domain.com We’ve also had a few newer Android phones like the Google Pixel’s pre-fill the word ‘anonymous’ in the ‘anonymous identity’ field, which users have to clear out to be able to connect or it fails with Reason Code 8 ‘The specified user account does not exist’.
  15. https://www.ifixit.com/Answers/View/171333/iPhone+5+stuck+on+recovery+mode+error+(9). seems to suggest Apple reject the restore with error code 9 when non-OEM hardware is installed. In that post, someone disconnected their 3rd party screen, restored from iTunes and then reconnected the screen after and it worked. Worth a shot!
×
×
  • Create New...